CWE-281
Improper Preservation of Permissions
The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.
337 vulnerabilities with CWE-281
CVE-2024-54515
HIGH
macOS Sequoia <15.2 - Privilege Escalation
CVSS 7.8
CVE-2024-54513
MEDIUM
Apple iPadOS < 18.2 - Unprotected User Data Exposure via Permissions Issue
CVSS 5.5
CVE-2024-54484
MEDIUM
macOS < 15.2 - Unprotected User Data Exposure via Log File Insertion
CVSS 5.5
CVE-2024-54465
CRITICAL
macOS Sequoia <15.2 - Privilege Escalation
CVSS 9.8
CVE-2024-50931
MEDIUM
Silicon Labs Z-Wave Series 500 <6.84.0 - Privilege Escalation
CVSS 4.6
CVE-2024-50930
HIGH
Silicon Labs Z-Wave Series 500 v6.84.0 - Arbitrary Code Execution
CVSS 8.8
CVE-2024-50929
MEDIUM
Silicon Labs Z-Wave SDK < 7.21.1 - Denial of Service via Device Type Manipulation
CVSS 6.2
CVE-2024-50928
MEDIUM
Silicon Labs Z-Wave <7.21.1 - Privilege Escalation
CVSS 6.5
CVE-2024-50924
MEDIUM
Silicon Labs Z-Wave Series 700/800 <7.21.1 - DoS
CVSS 6.5
CVE-2024-50921
MEDIUM
Silicon Labs Z-Wave SDK < 7.21.1 - Denial of Service via Crafted Packet Flood
CVSS 6.5
CVE-2024-50920
HIGH
Silicon Labs Z-Wave <7.21.1 - Privilege Escalation
CVSS 8.8
CVE-2024-41650
CRITICAL
Open Robotics Robotic Operating System 2 <v.humble - Code Injection
CVSS 9.8
CVE-2024-41649
CRITICAL
ROS2 Navigation2 Humble - executor_thread_ Arbitrary Code Execution
CVSS 9.8
CVE-2024-41648
CRITICAL
ROS2 Navigation2 Humble - Regulated Pure Pursuit Arbitrary Code Execution
CVSS 9.8
CVE-2024-41646
CRITICAL
Open Robotics Robotic Operating System 2 <v.humble - Code Injection
CVSS 9.8
CVE-2024-41645
CRITICAL
Open Robotics ROS2 navigation2 v.humble - Insecure Permissions
CVSS 9.8
CVE-2024-41644
CRITICAL
ROS2 Navigation2 Humble - dyn_param_handler_ Arbitrary Code Execution
CVSS 9.8
CVE-2024-37575
HIGH
Mister org.mistergroup.shouldianswer 1.4.264 - Unauthenticated Phone Call Placement via DefaultDialerActivity Intent
CVSS 7.5
CVE-2024-43784
MEDIUM
lakeFS <1.33.0 - Privilege Escalation
CVSS 5.7
CVE-2024-52522
MEDIUM
rclone 1.59.0-1.68.1 - Privilege Escalation via Symlink Permission Manipulation
CVE-2024-36062
MEDIUM
com.callassistant.android <1.174 - RCE
CVSS 4.0
CVE-2024-10458
HIGH
Firefox < 132 & Thunderbird < 132 - SSRF
CVSS 7.5
CVE-2024-44193
HIGH
iTunes <12.13.3 - Privilege Escalation
CVSS 7.8
CVE-2024-9333
MEDIUM
M-Files Connector for Copilot <24.9.3 - Auth Bypass
CVE-2024-44188
MEDIUM
macOS Sequoia <15 - Info Disclosure
CVSS 5.5
Details
Vulnerabilities
337